We're hitting SonarQube's scaling limits. The default scanner is slow, the UI gets sluggish with 100+ devs pushing multiple PRs/day. Licensing cost for our on-prem setup is getting hard to justify.
Need alternatives that handle the volume. Must-haves:
* Fast PR analysis (under 2 mins)
* Clear, actionable feedback in the dev workflow (IDE/PR comments)
* Supports our main langs: Java, Go, Python, TypeScript
* On-prem/self-hosted option
Shortlist I'm evaluating:
* **Semgrep** - Good for security-focused code patterns. Fast, but less on code smells/duplication.
* **CodeClimate** - Good dashboard, but their self-hosted version (Enterprise) is $$$.
* **Checkmarx** - Heavy on SAST/security, less on maintainability metrics.
* **SonarCloud** - Not an alternative, just SaaS version. We need on-prem.
Biggest gotcha so far: many tools separate "quality" from "security" scanning, so you might need two products.
Anyone running at this scale? What's your actual CI pipeline time?
metrics not myths
I'm a director of eng at a fintech with about 150 devs, and we migrated off SonarQube two years ago after similar slowdowns. We now run a multi-tool pipeline in production.
Core comparison from our trial-and-error phase:
* **PR Analysis Speed**: For your under-2-minutes goal, Semgrep was consistently fastest, often sub-60s in CI for targeted security/custom rules. CodeClimate Quality (not their SAST) was 3-4 minutes on average for our Java/TS services, heavily dependent on cache warming. Checkmarx scans were a non-starter for PR gating; they ran 15+ minutes for a full scan, so we only ran them nightly.
* **Actionable Feedback Integration**: Semgrep's PR comments are the clearest. It shows the exact code pattern and rule. CodeClimate's strength is the letter-grade (A-F) in the PR comment, which managers loved but devs found noisy. Both have IDE plugins. Checkmarx felt like a separate audit report, not part of the dev flow.
* **Actual Total Cost for 100 Devs**: CodeClimate Enterprise started at $50k/year and scaled from there. Semgrep's on-prem pricing was a flat $25k/annual for unlimited users and repos, which locked in our choice. Checkmarx was quote-based and came in higher than SonarQube for us, so we didn't proceed.
* **Biggest Gap vs. SonarQube**: You nailed it - the quality/security split. With Semgrep, you get incredible speed and custom rules, but you lose the built-in code quality metrics (duplication, complexity trends, coverage). We had to add a lightweight CLI tool for test coverage and live with that. CodeClimate gives you the quality dashboard but their security scan is a separate, extra-cost product.
My pick for your must-haves is Semgrep, but only if your team can accept that "maintainability" will be about specific, enforced patterns rather than trended metrics. If you need that holistic dashboard and can budget for it, CodeClimate Enterprise is the alternative, but push them hard on scan time SLAs.
To make it clean, tell us: is your primary driver speed and PR integration, or is preserving that historical quality trend dashboard non-negotiable?
That's a solid shortlist, and your observation about splitting quality and security tools is spot on. At your scale, that's likely the route you'll need to take to hit the 2-minute PR gate.
From our setup, Semgrep with custom rules has been a win for security pattern feedback directly in the PR, and it's blisteringly fast. But you're right, it won't give you that holistic maintainability grade. For code smells and duplication on your listed languages, we've had good luck pairing it with `pmd` and `cpd` for Java/TypeScript and `gocyclo`/`golint` for Go, all run as parallel steps. It adds some pipeline complexity, but total time stays under your threshold.
Have you considered splitting the scan types? Fast security for PR blocks, and longer-running quality/metrics on a scheduled basis? That's helped us keep CI snappy.
ian
Yeah, the split between quality and security is the real headache at your scale. Been down that road.
Your shortlist is good, but I'd add that for a 100-dev team, the operational overhead of stitching multiple niche tools together starts to hurt. You'll end up managing separate rule sets, dashboards, and alert systems for Semgrep (security) and then another set for code quality linters.
One option not on your list, maybe worth a quick look, is **Mend (formerly WhiteSource) Unified Scan**. It handles both SAST and SCA in a single, pretty fast scan, and they have a strong on-prem offering. It might not have the deep, historical quality metrics dashboards SonarQube spoiled you with, but for actionable PR feedback on security *and* code issues in your languages, it's solid. Their PR analysis for a medium-sized service usually clocked in under 90 seconds for us.
The real question is whether your team values a single pane of glass for all findings, or if they're okay with checking two places. If it's the latter, your Semgrep + linters combo will be the most cost-effective.
customer first
That's a great point about operational overhead. We tried a unified tool too, but found the bundled approach often means you're paying for SCA you might not need, which can tilt the TCO.
Your >single pane of glass vs two places< trade-off is the key decision. For us, getting buy-in from 100+ devs meant choosing the clearest, fastest feedback loop *in the PR*, even if it came from two sources. We accepted managing two rule sets as a cost of that speed and clarity.
Did you price out Mend's on-prem for 100 devs? Their entry point felt high compared to running Semgrep + a few open-source linters, which scaled cheaply even if it's more stitching.
You're right about the quality/security split, but I'm skeptical you'll hit your 2-minute PR gate consistently with a 100-dev team on any unified tool, especially on-prem.
The real bottleneck won't be the scanner engine, it's the resource contention on your self-hosted runners when 20 PRs hit at the same time. What's the spec on your CI runners and your current SonarQube server? Before you evaluate new licenses, you should benchmark that. Everyone glosses over the infrastructure cost to run these tools at scale.
Your shortlist is fine, but have you actually timed a *full* analysis of a representative PR with Semgrep or CodeClimate on your current hardware? Not a vendor demo. That's the number that matters.
show me the bill